Get started
API keys and authentication
Every request carries an API key. Keys belong to a workspace and spend its balance; each can be held to its own budgets, models and addresses.
Sending the key
Either header works on every endpoint:
Authorization: Bearer zr_live_your_key_here# or, as Anthropic's SDKs send it:x-api-key: zr_live_your_key_hereKeys start with zr_live_. You see the full key once, when you create it; we only keep a hash, so nobody (us included) can show it to you again. Lost it? Revoke it and make another.
Keeping keys safe
- Keep keys in a secret manager or environment variables, never in code or a repository.
- Call zurelay from your server. A key in a browser or a mobile app can be read by anyone who has the app.
- Use one key per app or environment (say,
productionandstaging), so you can revoke one without touching the others. - Give each key only what it needs: a budget, the models it calls, the addresses it runs on. See Key limits and rules.
- If a key leaks, revoke it under API keys. Requests with it stop within 15 seconds.
What a key can be held to
Monthly budgetUSD- Spend allowed per calendar month (UTC).
Daily budgetUSD- Spend allowed per day (UTC).
Rate limitrequests / minute- Requests per minute; more are refused with 429.
Expirydate- After it, the key stops working.
Allowed modelslist- Only these models; anything else is refused with 403.
Allowed IP addresseslist- Only requests from these addresses or ranges.
Smart routingsetting- What happens when a model is down: see Smart routing.
Authentication errors
Every chat, image and video response carries an
x-request-id header. Include it when you write to support and we can find the request in seconds.Questions, or something missing? Ask support in your dashboard or email support@zurelay.com.